โ† All reports

The Vvveb software by givanz has known security vulnerabilities that could allow unauthorized access or execution of arbitrary code.

CybersecurityTechnologyConflictInformation SecurityApr 20, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two security vulnerabilities in the Vvveb product by givanz, specifically a server-side request forgery and a stored cross-site scripting vulnerability, both affecting versions prior to 1.0.8.1. These vulnerabilities highlight potential security risks in the software, which could be exploited by authenticated users.

Claims

The Vvveb software by givanz has known security vulnerabilities that could allow unauthorized access or execution of arbitrary code.
Parent: CybersecurityEntity: Vvveb software by givanzImpact: negativeDate: Apr 20, 2026Target: The security of the Vvveb software by givanz

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-23854 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Vvveb, Vvveb ๐Ÿข Vendor: givanz ๐Ÿ“… Updated: 2026-04-20 ๐Ÿ“ Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media upload and rename permissions to execute arbitrary JavaScript by bypassing MIME type validation and renaming uploaded files to executab... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23854 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23852 ๐Ÿ“Š Score: 8.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Vvveb, Vvveb ๐Ÿข Vendor: givanz ๐Ÿ“… Updated: 2026-04-20 ๐Ÿ“ Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the url parameter is passed directly to getUrl() via curl without scheme or destination validation. Authenticated back... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23852 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability